EDBT 2026 Demo / reviewers in the wild / expert
Emmanuel Syrmoudis
dblp:293/2325
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0002-0436-2143ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unlocking personal data from online services: user studies on data export experiences and data transfer scenariosabstractIn recent years, online services have started to make personal data of users more accessible by offering dedicated ways of exporting data. The introduction of download portals is associated with increasing demands by privacy regulations regarding the rights of users, such as the Right of Access (Art. 15) and the Right to Data Portability (Art. 20) of the European Union’s General Data Protection Regulation (GDPR). These rights aim to empower users by increasing their control over the personal data that online services hold about them. They allow users to export their personal data and thereby gain insights on the scope of personal data held by the services and to transfer this data to other services. However, until now, little is known about how users experience and evaluate the process of accessing and exporting their data and how it impacts individual-level factors such as privacy-related attitudes (i.e. attitudes regarding sharing personal data, perceived control over data, and using privacy-protective strategies). In this paper, we report the results of an online survey with an experimental condition (N = 728) and a second online survey (N = 817) where participants from two university courses were asked to request real data exports from online services and inspect the exported data afterward. We find that inspecting exported personal data has a statistically significant positive effect on users’ privacy-related attitudes. However, users perceive limited usefulness in switching scenarios where personal data is transferred to a new substitutional service and rather prefer to use the data at multiple complementary services. Emmanuel Syrmoudis, Robert Luzsa, Yvonne Ehrlich, Dennis Agidigbi, Kai Kirsch, Danny Rudolf, Daniel Schlaeger, Joelle Weber, Jens Grossklags |
Hum. Comput. Interact. | 1 |
| 2026 | Analyzing Societal Awareness and Perception of Digital Fingerprinting and Fingerprinting CountermeasuresabstractWe explore societal awareness and perceptions related to digital fingerprinting, a stateless tracking technology increasingly used for online security, advertising, and fraud prevention, as well as to countermeasures designed to mitigate its impact. Despite its widespread application, user awareness of fingerprinting remains significantly lower compared to other tracking mechanisms, such as third-party cookies. To deepen our understanding of user perceptions, we conducted a study surveying 734 participants to assess their knowledge of fingerprinting, acceptance of its use across different applications (cybersecurity, law enforcement, user experience), and their reactions to browsing inconveniences introduced by countermeasures. Countermeasures examined include privacy-focused browsers (e.g., Tor), browser extensions, and spoofing tools. While these solutions vary in effectiveness, they often compromise usability, resulting in issues such as website breakages and prolonged CAPTCHA challenges. Privacy-conscious users demonstrated greater tolerance for such disruptions, whereas others prioritized convenience over protection. Pascal Schramm, Emmanuel Syrmoudis, Alexandros Markou, Jens Grossklags |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | A Longitudinal Analysis of Corporate Data Portability Practices Across IndustriesabstractLock-in practices of online services hinder consumers from switching frictionlessly to a competitor once they are unsatisfied with the company’s service offering, privacy practices, or philosophy. The right to data portability (RtDP) is one of the strongest measures introduced by recent privacy regulations to unlock continuously collected user data from centralized silos of market leaders. Introducing the obligation to provide means of data transfers between services, it aims to establish decentralized online markets and to foster competition. In this longitudinal study comprising a unique dataset of 129 online services over three consecutive years, we are the first to provide evidence on the development of the effectiveness of the EU’s RtDP. Astonishingly, only 16% of services could provide a compliant data export in all years, with services from the industries Entertainment and Travel performing worst. Overall, Finance & Insurance and Social Networks & Messaging include the services with the highest compliance rates. Regarding the usefulness of data portability, our analysis unveils that data export scope and data import options have stagnated between 2020 and 2022. Further, we are able to show that online services with a high presence of third-party trackers are less compliant and ready to export data from their systems. Lastly, our regression analyses show that service popularity significantly increases format compliance, export scope, and import options. This suggests that competitors to incumbents still perceive the regulation more as a bureaucratic burden than a unique opportunity to attract new consumers and their data. Emmanuel Syrmoudis, Stefan Mager, Jens Grossklags |
ACSAC | 1 |
| 2022 | Leave No Data Behind - Empirical Insights into Data Erasure from Online ServicesabstractPrivacy regulations such as the General Data Protection Regulation (GDPR) of the European Union promise to empower users of online services and to strengthen competition in online markets. Its Article 17, the Right to Erasure (Right to be Forgotten), is part of a set of user rights that aim to give users more control over their data by allowing them to switch between services more easily and to delete their data from the old service. In our study, we investigated the data deletion practices of a sample of 90 online services. In a twostage process, we first request the erasure of our data and analyze to what extent public data (e.g., posts on a social network) remains accessible in a non-anonymized format. More than six months later, we request information on our data using Right of Access requests under Art. 15 GDPR to find out if and what data remains. Our results show that a majority of services perform data erasures without observable breaches of the provisions of Art. 17 GDPR. At 27%, the share of non-compliant services is not negligible; in particular, we observe differences between requests submitted using a dedicated button and formal requests under Art. 17 GDPR. Eduard Rupp, Emmanuel Syrmoudis, Jens Grossklags |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Data Portability between Online Services: An Empirical Analysis on the Effectiveness of GDPR Art. 20abstractAbstract Data portability regulation has promised that individuals will be easily able to transfer their personal data between online service providers. Yet, after more than two years of an active privacy regulation regime in the European Union, this promise is far from being fulfilled. Given the lack of a functioning infrastructure for direct data portability between multiple providers, we investigate in our study how easily an individual could currently make use of an indirect data transfer between providers. We define such porting as a two-step transfer: firstly, requesting a data export from one provider, followed secondly by the import of the obtained data to another provider. To answer this question, we examine the data export practices of 182 online services, including the top one hundred visited websites in Germany according to the Alexa ranking, as well as their data import capabilities. Our main results show that high-ranking services, which primarily represent incumbents of key online markets, provide significantly larger data export scope and increased import possibilities than their lower-ranking competitors. Moreover, they establish more thorough authentication of individuals before export. These first empirical results challenge the theoretical literature on data portability, according to which, it would be expected that incumbents only complied with the minimal possible export scope in order to not lose exclusive consumer data to market competitors free-of-charge. We attribute the practices of incumbents observed in our study to the absence of an infrastructure realizing direct data portability. Emmanuel Syrmoudis, Stefan Mager, Sophie Kuebler-Wachendorff, Paul Pizzinini, Jens Grossklags, Johann Kranz |
Proc. Priv. Enhancing Technol. | 1 |